azure
Warn
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill serves as a wrapper for the Azure CLI (
az), allowing the agent to perform a wide range of administrative operations on Azure resources. - [REMOTE_CODE_EXECUTION]: The
vm-run-commandtool enables the execution of arbitrary shell scripts on remote Azure Virtual Machines using theaz vm run-command invokecommand, which bypasses network-level access controls to the VM. - [CREDENTIALS_UNSAFE]: The
aks-credentialstool allows for the extraction of Kubernetes cluster credentials, including administrative access (--admin), which are then persisted to the local kubeconfig file. - [DATA_EXFILTRATION]: The
storage-blob-uploadandstorage-blob-downloadtools provide the capability to move data between the local system and Azure Blob Storage, presenting a potential path for data exfiltration or the introduction of malicious payloads.
Audit Metadata